Activity timeline
T1053 first appeared in tracked threats on and was most recently reported on . The busiest month was 2026-07 with 77 reports, and 270 of the 271 threats were reported in the twelve months to 2026-09.
How adversaries use it
T1053 Scheduled Task/Job is catalogued by MITRE ATT&CK under the Execution and Persistence and Privilege Escalation tactics in the Enterprise matrix. Threadlinqs maps 271 of 2623 tracked threats (10.3%) to it; by severity that is 94 critical, 162 high, 12 medium, 2 low.
Threats that use T1053 most often also use T1059 Command and Scripting Interpreter (234 threats), T1071 Application Layer Protocol (211 threats), T1027 Obfuscated Files or Information (203 threats), T1036 Masquerading (193 threats), T1082 System Information Discovery (187 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.
102 tracked threat actors appear in the threats that use T1053; the most frequent are APT28 (8), Forest Blizzard (7), APT38 (6), BlueDelta (6), TeamPCP (6).
Mitigations
MITRE ATT&CK lists 5 mitigations for T1053.
Data sources
Telemetry that can reveal T1053, per MITRE ATT&CK.
- Command — Command Execution
- Container — Container Creation
- File — File Creation, File Modification
- Process — Process Creation
- Scheduled Job — Scheduled Job Creation
Threat actors using it
Tracked threats
The 30 most recent of 271 tracked threats that use T1053.
- UTA0565 Chains Chrome and Windows Zero-Days (CVE-2026-85046, CVE-2026-87491, CVE-2026-85880) to Deploy…critical
- CISA Adds Two Actively Exploited KEVs: SharePoint Code Injection (CVE-2026-65660) and Mikrotik RouterOS Auth…critical
- TokenGrabber: Python-based MaaS Infostealer Builderhigh
- Operation RapidRust: APT36 Deploys RUSTYSHADE, RUSTYMOVE, PSNATCH, and BASHNATCH Against India and…high
- KREMLIN Banking Malware Hijacks Chrome and Edge via Phantom Extension/GhostChrome-X Integrity Bypass to…high
- Compromised HBO Max Reddit Account Distributes ClickFix Malware in "PasteSwitch" Cross-Platform Malvertising…high
- Infostealer Logs Expose Replayable AI Session Tokens and API Keys Enabling MFA Bypasshigh
- QuimaRAT v2.0 — Java-Based Cross-Platform Remote Access Trojan Offered as Malware-as-a-Servicehigh
- REVSTEALER (REF2859): Emerging Windows infostealer with App-Bound encryption bypass, Polygon blockchain C2…high
- Fake GlobalProtect MSI Targets Myanmar Using Cloudflare Workers and Google Sheets API as C2high
- FalconFlank Zero-Day Local Privilege Escalation in CrowdStrike Falcon Sensor via Office Macro Remediation…high
- StyleSmuggler — Magento Open Source and Adobe Commerce Unauthenticated RCE 0-Day Under Active Exploitationcritical
- Attackers Hijack MikroTik Routers Through Internet-Exposed SSH Without Authentication (MikroTrick)critical
- Node.js Living-off-the-Land: Multiple Threat Actors Abuse Signed node.exe as a Script Interpreter, Feeding…high
- Mustang Panda Targets India's Government and Energy Sectors with SHARDLOADER, MINIRECON, and ZOHOMURKhigh
- Aur0ra Ransomware Group: Xray-core C2 Tunneling, Aggressive Email Bombing, and Log-Wiping Double-Extortion…high
- "Spring Ring" Vishing Campaign Abuses Microsoft Teams, Quick Assist, and PetitPotam for NTLM Relayhigh
- Infostealer Malware (Vidar, LummaC2, StealC, RedLine, Acreed, Atomic Stealer) Hijacking Claude Login…medium
- Spark RAT Campaign Targets Cambodia via BYOVD Abuse of Vulnerable OPSWAT AppRemover Driver (CVE-2026-36425)high
- SynkLoader: New Multi-Module Malware Family Distributed via Microsoft Teams Phishing Campaign Targeting…high
- LockBit 5.0 Ransomware Extortion Claim Against US Bank (U.S. Bancorp)high
- SilkParasite: China-Nexus Cyber Espionage Campaign Targeting Central Asian Governmentscritical
- SilkParasite: China-Nexus APT Campaign Using 7 Malware Families Across Central Asiahigh
- WordlistLoader Delivering Amatera (ACR Stealer) via ClearFake FakeCaptcha Campaignshigh
- Russia (GRU Unit 26165 / APT28) Runs Multi-Vector Surveillance, Intimidation, Sabotage and Cyber Espionage…high
- Kimsuky 'Operation GitPower' Integrates Local AI Tooling into AsyncRAT Espionage Campaignhigh
- TXTBOOK: Dependency Confusion Campaign Drops Sliver via DNS TXT-Record Staging Against T-Bankhigh
- Odysseus AI Workspace Remote Code Execution via Authorization Bypass — GHSA-xwhc-f36c-v5vm (CVSS 9.9)critical
- GOLD ENCOUNTER / Payouts King Ransomware Campaign Targeting Business Managers: 351 Victims Across 334…high
- CVE-2026-9198 — Unauthenticated RCE in IBM Langflow Under Active Exploitation (Auto-Login Bypass + Code…critical
Detection coverage
Threadlinqs maintains 56 detection rules mapped to T1053 (SPL 20, KQL 18, Sigma 18). Rule content is available to Blue tier accounts and above; this page shows counts only.
Sub-techniques
- T1053.001 At (Linux) — 0 tracked threats
- T1053.002 At — 1 tracked threat
- T1053.003 Cron — 61 tracked threats
- T1053.004 Launchd — 1 tracked threat
- T1053.005 Scheduled Task — 216 tracked threats
- T1053.006 Systemd Timers — 3 tracked threats
- T1053.007 Container Orchestration Job — 0 tracked threats